Responsible Disclosure & Vulnerability Reporting
How security researchers and users can responsibly report a potential vulnerability in BLYQUE.
1. Purpose
This policy sets out a responsible process for reporting security vulnerabilities in BLYQUE. When you submit a report, we review it, may ask you for more information, keep investigation records, coordinate the fix, preserve evidence where legally required, and take whatever action is appropriate to protect the platform.
2. Scope
This policy covers BLYQUE's websites, applications, APIs, and any other services we support.
3. Good-faith research
We welcome security research that is conducted in good faith and in line with this policy.
4. How to report
When you report a vulnerability, please include enough technical detail for us to reproduce and validate the issue — the steps you took, the affected component, and what you observed.
5. What not to do while testing
While researching a potential vulnerability, please don't access data you don't need, disrupt the service for other users, or break any applicable law.
6. Our response
We aim to acknowledge reports, investigate the findings, and prioritize remediation based on the level of risk involved.
7. Confidentiality
Please keep any vulnerability you find confidential until it's resolved or we've authorized disclosure — this protects our users while a fix is in progress.
8. No guarantee of reward
Unless BLYQUE runs a separate bug bounty program, submitting a report does not guarantee payment or any other form of compensation.
9. Legal compliance
Everyone involved — researchers and BLYQUE alike — is expected to comply with applicable law and to respect user privacy throughout the process.
10. Policy updates
This policy may be updated to reflect changes in our security practices or in applicable legal requirements.